Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T19BA3B7B231C6983C63FB97C595543919F284CA07C9748FC8E798C2CCE6EDA915AE325C |
|
CONTENT
ssdeep
|
768:5yh44CrlPlKsvYoD/hCh9zSp58BcTiCB8UK7jl+y+zyG+4JrW/aX5Q2kLxe+M1ZQ:oh44CK8n4Lkojl+y+z8E+M1ZC0Of |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
96336c6e394c333c |
|
VISUAL
aHash
|
006e6e7c0c3c1000 |
|
VISUAL
dHash
|
d4c8dcc828682430 |
|
VISUAL
wHash
|
007e7e7e0c7e1c1c |
|
VISUAL
colorHash
|
00007000000 |
|
VISUAL
cropResistant
|
dce1d0c9c913db96,b0b27860e4c8f1f8,d4c8dcc828682430 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 11 techniques to evade detection by security scanners and make reverse engineering more difficult.